You can put an auth cookie in a browser and achieve 2FA for 99% of use cases without bothering anyone.
But nobody does that when they can use 2FA as an excuse to force people to install their app or hand over more personal information.
No reason 2FA can't be just two passwords.
Confusing, obviously incorrect.
> No reason 2FA can't be just two passwords.
Maybe somewhat less obviously incorrect, but still incorrect. Passwords can be phished easily, are managed by users, etc.
If you really must protect the user from themself (which I don't think you should, except in much more extreme circumstances), you can generate the password for them.
You know what is less secure than a password? A phone. A phone is a sim swap away from being hacked at anytime.
That's not two factors, that's one factor (something you know) twice, even if it is different passwords.
In the general sense perhaps. As it's commonly implemented, no not really.